INTRODUCTION
This Privacy Notice (“Notice”) is about the processing of your data by Philips for purposes of repairing or replacing eligible device(s) pursuant to the medical device recall notification issued by Philips in June 2021 (“Remediation”). It explains how we process your data on the self-service applications supporting Remediation (“Portals”) for the purposes outlined below, and includes what data we collect, why we collect it, what we do with it, and how we protect it, as well as your individual rights.
WHAT TYPES OF DATA DO WE PROCESS?
Philips will receive and process certain data you provide through the Portals, which may include the following categories:
- Personal characteristics (e.g., date of birth, gender, demographics)
- Contact information (e.g., name, residential address, e-mail address, telephone number)
- Information about your registered device (e.g., visualization of particulates, use of certain sterilization products, whether you actively use the device)
- Health and prioritization-related information (e.g., underlying medical conditions, pregnancy status, occupation, motor vehicle accident history related to sleep deprivation)
- Other sensitive information (certain occupations, motor vehicle accident history)
- Electronic identification data (IP address, cookies, etc.)
THE LEGAL BASES RELIED UPON TO PROCESS YOUR DATA
Philips processes your data for the purposes mentioned above only when we have a lawful basis to do so, as follows:
- We will process your data in the interest of public health and safety, specifically in connection to the medical device recall notification issued by Philips in June 2021
- We may process your data for Philips’ legitimate interests, such as to ensure our medical devices and services adhere to a high standard of quality and safety, but will only do so when we’ve concluded that the processing will not outweigh your applicable privacy rights and interests
- We may process your data in order to comply with a legal or regulatory obligation to which Philips is subject, for example, if we are requested by a governmental authority to disclose your data for audit purposes.
Outside of the purposes and legal bases described above, Philips will not process your data without first obtaining your express consent.
WITH WHOM DO WE SHARE YOUR DATA?
Your data may be shared with other Philips affiliates who are part of the Philips Group. Only people (within Philips) who have a need to know the information will have access to the information.
In addition, Philips is working with certain external parties in order to faciliate the Remediation of eligible devices, including:
- Service Providers. We have contracted with trusted third party companies that provide products and services to us such as IT systems and customer/technical support:
- Public and Governmental Authorities. When required by law, or as necessary to protect our rights, we may share your data to public and governmental authorities that regulate or have jurisdiction over Philips. In particular, Philips is required to comply with certain recall-related requests from the U.S. Food and Drug Administration (FDA).
- Other parties in connection with corporate transactions. We may also, from time to time, share your data in the course of corporate transactions, such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of Philips’ business, assets, or stock.
HOW LONG DO WE KEEP YOUR DATA?
We keep your data as long as needed to fulfill the purposes for which it has been collected. The criteria used to determine our retention periods include:
- How long your data is needed to faciliate the Remediation process,
- Whether Philips is subject to any legal or regulatory obligations to keep your data,
- How long your data is needed to fulfill any other purposes for which it was collected.
In light of the above criteria, your data will be permanently deleted fifteen (15) years after the eligible device(s) end of life.
WHAT ARE YOUR PRIVACY RIGHTS?
To the extent required by applicable law, you have certain rights with respect to the processing of your data which enable you to:
- obtain information on the processing of your data,
- obtain a copy of your data in a machine-readable format,
- object to the processing of your data,
- have your data rectified or deleted or their processing restricted (to the extent permitted by applicable law), and
- withdraw consent (if applicable) that you might have given with respect to the processing of your data without any consequence for you.
To exercise your rights or to ask any other questions related to the protection of your data in Philips or regarding this Notice in general, you can contact the Philips Data Protection Officer via www.philips.com/contactprivacy or by regular mail at:
Philips - Attn: Group Legal (Privacy)
Philips Center HBT 16, Amstelplein 2
1096 BC, Amsterdam, The Netherlands.
If you are not satisfied with Philips’ response or believe that your data is not being processed in accordance with the law, you may contact or lodge a complaint with the competent data protection authority or seek other remedies under applicable law.